06 Mar 2007
Attackers have injected exploit code into the downloadable software for the WordPress blogging service.
The open source software allows users to set up and publish postings to a blog. The company has issued an update that repairs the vulnerability.
Although blogging services such as Blogger, TypePad and WordPress allow users to publish blog postings directly from a browser, client software offers users more flexibility.
Hackers broke into the WordPress download server early last week and embedded attack code into the 2.1.1 update of the application.
The malware opened a backdoor on infected systems that could allow an attacker to execute code and install software.
WordPress founding developer Matthew Mullenweg said on a company blog that the infected software was offered to users for three to four days as an official download before the company was alerted to the breach.
"This is the kind of thing you pray never happens," said Mullenweg. "But it did and we are dealing with it as best we can."
Security vendor Symantec said that it had uncovered fewer than 50 attacks exploiting the backdoor. The firm rated the threat as 'low-level' because of its limited reach and easy removal.
WordPress is recommending all users to upgrade to version 2.1.2 of the software, and has urged administrators hosting WordPress blogs to prevent access to the 'theme.php' and 'feed.php' files that are infected by the attack.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
Helpdesk/Service Analyst x 3 3 Month Contract...
French Technical support Specialist (2/3rd Line) CCNA...
ECM Project Manager - CMS, "Document Management", Web...
Skills - Presales, Consultant / Consultancy, Technical...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?